The four rights and their statutory basis
The DPDPA grants Data Principals four categories of rights:
| Right | Section | What the Data Fiduciary must do |
|---|---|---|
| Access and summary | Section 11 | Provide a summary of the personal data being processed and the processing activities, and the identities of all Data Fiduciaries and Data Processors with whom the data has been shared |
| Correction and erasure | Section 12 | Correct inaccurate or misleading personal data, complete incomplete data, update personal data, and erase personal data no longer necessary for the purpose |
| Grievance redressal | Section 13 | Respond to any grievance about the processing of personal data within the timelines in Rule 14 |
| Nomination | Section 14 | Allow the Data Principal to nominate another person to exercise their rights in the event of death or incapacity |
Section 15 lists the duties of Data Principals. Section 12(3) provides that erasure is subject to compliance with any law that requires retention.
The end-to-end DSAR handling process
A DSAR process must cover receipt, verification, fulfilment and evidence:
- 01
Receive the request
Provide a clear channel (email, web form, in-app) for Data Principals to submit requests. Rule 9 requires published contact details.
- 02
Acknowledge and log
Acknowledge the request within the prescribed timeline. Log the date, type of request, identity of the Data Principal and the assigned handler.
- 03
Verify identity
Confirm the identity of the Data Principal before disclosing any personal data. Use the same authentication method the Data Principal used to provide the data, or an equivalent.
- 04
Locate the data
Search all systems, vendors and processors identified in the RoPA for personal data relating to the Data Principal.
- 05
Fulfil the request
For access: prepare a summary. For correction: update the records. For erasure: delete or anonymise, and notify each Data Processor (Section 8(2)). For nomination: record the nominee.
- 06
Respond to the Data Principal
Send the response within the prescribed timeline. If the request is refused (for example, retention is required by law), state the reason.
- 07
Record the evidence
Store the request, the verification step, the actions taken, the response sent and the date. This is the evidence for an audit or a Board inquiry.
Grievance redressal and Board escalation
Section 13 gives the Data Principal the right to have any grievance about the processing of personal data addressed by the Data Fiduciary. The grievance mechanism must be accessible and the response timely.
If the Data Principal is not satisfied with the response, Section 13(2) allows the complaint to be taken to the Data Protection Board. The Board may then initiate an inquiry under Section 28.
This escalation path means the grievance process is not just an internal function. It is the first step in the enforcement chain. A well-run grievance process reduces Board complaints; a badly-run one generates them.
The evidence trail for each request
In a Board inquiry, the organisation must show how it handled rights requests. The evidence includes:
- The request log: date, type, Data Principal identity, handler, dates of each step.
- The verification record: how identity was confirmed.
- The action record: what data was accessed, corrected, erased or retained, and the reason.
- The response: the communication sent to the Data Principal, with the date.
- The processor notification: if erasure was requested, the notification sent to each Data Processor under Section 8(2).
How AMLEGALS helps set up DSAR handling
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team designs the DSAR workflow, the verification protocol, the response templates, the evidence log and the escalation procedure. For ongoing support, the DSAR handling process is covered under a compliance retainer.

